HIPAA Notice
Last updated: August 20, 2026
MedicalAgentOS is designed with a HIPAA-aware architecture and operates as a business associate to covered entities (medical practices and healthcare organizations) that use the Service to process protected health information (PHI).
Our role
The practice remains the covered entity and data controller for its patients' PHI. MedicalAgentOS processes PHI solely to provide the Service, as directed by the practice and as permitted by the Business Associate Agreement (BAA) executed with each customer.
Safeguards
- Encryption of PHI in transit (TLS 1.2+) and at rest (AES-256).
- Role-based access control with fine-grained permissions and least privilege.
- Multi-factor authentication and strong session management.
- Server-side tenant isolation for every organization and practice.
- Comprehensive audit logging of every material action, human or AI.
- Human approval workflows for clinical and high-risk AI outputs.
- Workforce security training and access reviews.
- Subprocessors bound by BAAs where they handle PHI.
Important note on compliance
HIPAA compliance is a shared responsibility. Our platform provides technical controls, contracts, and product behavior designed to support compliance — but a practice's overall compliance also depends on its own policies, procedures, training, and use of the Service. We do not claim that use of MedicalAgentOS automatically makes a practice HIPAA compliant.
Breach notification
We maintain incident response procedures and will notify affected customers without unreasonable delay and within the timeframes required by the HITECH Act and the BAA.
Questions
compliance@medicalagentos.com